08Industries · Education
Every lab seat, the right student
Campuses run on shared lab machines, a new intake every year, and staff who work across many systems. SenseCrypt signs everyone in with a live face on their own phone, and the lab PC holds no credentials.
01The ceremony
From student record to the lab seat
Student or staff record
SCIM brings the account and its group memberships
Verify live at any lab seat
Scan the on-screen code, glance at their own phone
Learning platform opens
OIDC or SAML, scoped to the role
Named events + revocation
Person-level audit; access ends when enrollment does
02The outcomes
What campuses get from SenseCrypt
Students in without passwords
Students approve sign-in on the phone they already carry, for the learning platform, library, and portal alike. There is no password to forget, and none to lend.
Shared labs, personal sign-in
Students scan the on-screen code and glance at their own phone. The lab machine needs no enrollment and holds no credentials.
Step-up that names the request
Before a change to fee-payment details or another sensitive request, the prompt names the exact action, and only the enrolled student's live face can approve it.
No password to reset
A lost or new phone is re-bound with a one-time PIN sent to the contact details already on the account. Then the student signs in by face again.
Each intake, provisioned on time
Enroll from the photo already on file and provision through SCIM. When a course or contract ends, revoke the whole cohort in one pass.
Least privilege, by role
Roles and scopes keep teaching, research, and administration systems on separate permissions.
No rip-and-replace
If the learning platform or student-records system speaks OIDC or SAML, it already speaks SenseCrypt.
Partner portals, isolated
Partner institutions and vendors each get a tenant of their own: users, branding, and audit trail kept separate.
03The failure modes
What gets in the way today
Passwords lent and reused
Passwords get lent to friends and reused on other sites, and every copy is another way into the learning platform.
Lab machines everyone touches
A session left open on a lab PC becomes the next student's login, and the logs can't say who did what.
A new intake every year
Whole cohorts join and leave on the academic calendar. Provisioning and deprovisioning by hand leaves stale accounts behind.
Reset season
The start of term brings a wave of forgotten passwords, and the help desk answers them one ticket at a time.
Research data behind reused passwords
Research data and student records sit behind the same credentials people use everywhere else.
A login for every system
The learning platform, library, email, and records system each grew their own sign-in, and students and staff carry them all.
04The compliance map
What the regulator sees
No passwords to leak, and no face image or template on file, only sealed, unlinkable tokens that even we cannot reverse into a face and that carry no PII. One less sensitive store for the campus to account for.
GDPR — data minimisation (Art. 5(1)(c))
Students and staff verify without any stored face image or template, so the only thing held is a sealed, unlinkable token that even we cannot reverse into a face and that holds no PII. That supports GDPR's data-minimization principle.
Read the sourceNIST SP 800-207 — Zero Trust Architecture
Every lab sign-in is a fresh verification of the named student or staff member, and the campus network grants no trust on its own. That maps to the Zero Trust tenets of per-session access with least privilege, where network location alone does not imply trust.
Read the sourceFace matching in SenseCrypt is independently evaluated in the Face Recognition Technology Evaluation under Seventh Sense's own name, with results anyone can inspect. See the NIST report card (seventhsense-000)
Give every term a clean start
Try a real sign-in in the live demo, then run one lab on the free 30-day trial.